Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
2525 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.19% | — | Bainternet User Specific ContentAI | 31/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bainternet User Specific Content user-specific-content allows DOM-Based XSS.This issue affects User Specific Content: from n/a through <= 1.0.6. | |
| Analizada | Alta (8.8) | 0.17% | — | Bitdefender AntivirusBitdefender Antivirus PlusBitdefender Endpoint Security ToolsBitdefender Internet Security+1 | 10/12/2025 | 17/6/2026 | A local privilege escalation vulnerability in Bitdefender Total Security versions prior to 27.0.47.241 allows low-privileged attackers to elevate privileges. The issue arises from bdservicehost.exe deleting files from a user-writable directory (C:\ProgramData\Atc\Feedback) without proper symbolic link validation,… | |
| Aplazada | Alta (7.5) | 0.54% | — | SAP WEB DispatcherAISAP Internet Communication ManagerAISAP Content ServerAI | 9/12/2025 | 17/6/2026 | SAP Web Dispatcher, Internet Communication Manager (ICM), and SAP Content Server allow an unauthenticated user to exploit logical errors that lead to a memory corruption vulnerability. This results in high impact on the availability with no impact on confidentiality or integrity of the application. | |
| Aplazada | Media (6.6) | 0.34% | — | SAP Internet Communication FrameworkAI | 9/12/2025 | 17/6/2026 | The SAP Internet Communication Framework does not conduct any authentication checks for features that need user identification allowing an attacker to reuse authorization tokens, violating secure authentication practices causing low impact on Confidentiality, Integrity and Availability of the application. | |
| Analizada | Media (5.5) | 0.12% | — | Samsung Internet | 2/12/2025 | 25/9/2026 | Improper input validation in Samsung Internet prior to version 29.0.0.48 allows local attackers to inject arbitrary script. | |
| Analizada | Media (5.5) | 0.39% | — | Itsourcecode Web-based Internet Laboratory Management System | 17/11/2025 | 17/6/2026 | A vulnerability was found in itsourcecode Web-Based Internet Laboratory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /subject/controller.php. The manipulation results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and… | |
| Analizada | Media (5.5) | 0.39% | — | Itsourcecode Web-based Internet Laboratory Management System | 17/11/2025 | 17/6/2026 | A vulnerability has been found in itsourcecode Web-Based Internet Laboratory Management System 1.0. Affected is an unknown function of the file /settings/controller.php. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Modificada | Media (5.5) | 0.39% | — | Itsourcecode Web-based Internet Laboratory Management System | 17/11/2025 | 17/6/2026 | A flaw has been found in itsourcecode Web-Based Internet Laboratory Management System 1.0. This impacts an unknown function of the file /user/controller.php. Executing a manipulation can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. | |
| Modificada | Media (5.5) | 0.41% | — | Itsourcecode Web-based Internet Laboratory Management System | 17/11/2025 | 17/6/2026 | A vulnerability was detected in itsourcecode Web-Based Internet Laboratory Management System 1.0. This affects an unknown function of the file /enrollment/controller.php. Performing a manipulation results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. | |
| Analizada | Media (5.5) | 0.39% | — | Itsourcecode Web-based Internet Laboratory Management System | 17/11/2025 | 17/6/2026 | A security vulnerability has been detected in itsourcecode Web-Based Internet Laboratory Management System 1.0. The impacted element is an unknown function of the file /course/controller.php. Such manipulation leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may… | |
| Modificada | Crítica (9.1) | 0.25% | — | Tonec Internet Download Manager | 5/11/2025 | 5/7/2026 | Tonec Internet Download Manager 6.42.41.1 and earlier suffers from Missing SSL Certificate Validation, which allows attackers to bypass update protections. | |
| Aplazada | Media (5.4) | 0.31% | — | Horato Internet Technologies Ind. AND Trade INC Virtual Library PlatformAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Horato Internet Technologies Ind. And Trade Inc. Virtual Library Platform allows Reflected XSS. This issue affects Virtual Library Platform: before v202. | |
| Analizada | Media (4.9) | 0.27% | — | Internet2 Grouper | 19/9/2025 | 17/6/2026 | In Internet2 Grouper 5.17.1 before 5.20.5, group admins who are not Grouper sysadmins can configure loader jobs. | |
| Analizada | Media (5.5) | 0.48% | — | Itsourcecode Web-based Internet Laboratory Management System | 17/9/2025 | 25/9/2026 | A security flaw has been discovered in itsourcecode Web-Based Internet Laboratory Management System 1.0. Impacted is the function User::AuthenticateUser of the file login.php. Performing manipulation of the argument user_email results in sql injection. Remote exploitation of the attack is possible. The exploit has… | |
| Aplazada | Crítica (9.4) | 1.5% | — | InternetarchiveAI | 6/9/2025 | 17/6/2026 | internetarchive is a Python and Command-Line Interface to Archive.org In versions 5.5.0 and below, there is a directory traversal (path traversal) vulnerability in the File.download() method of the internetarchive library. The file.download() method does not properly sanitize user-supplied filenames or validate the… | |
| Aplazada | Alta (8.5) | 0.56% | 💥 Exploit | Agnitum Outpost Internet SecurityAI | 1/8/2025 | 16/6/2026 | A local privilege escalation vulnerability exists in Agnitum Outpost Internet Security 8.1 that allows an unprivileged user to execute arbitrary code with SYSTEM privileges. The flaw resides in the acs.exe component, which exposes a named pipe that accepts unauthenticated commands. By exploiting a directory traversal… | |
| Aplazada | Alta (8.5) | 0.37% | 💥 Exploit | Pandasecurity Global ProtectionAIPandasecurity Antivirus PROAIPandasecurity Small Business ProtectionAIPandasecurity Internet SecurityAI | 15/7/2025 | 17/6/2026 | PSEvents.exe in multiple Panda Security products runs hourly with SYSTEM privileges and loads DLL files from a user-writable directory without proper validation. An attacker with low-privileged access who can write DLL files to the monitored directory can achieve arbitrary code execution with SYSTEM privileges.… | |
| Analizada | Baja (2.9) | 0.69% | — | Comodo Internet Security | 6/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Comodo Internet Security Premium 12.3.4.8162. Affected is an unknown function of the component File Name Handler. The manipulation of the argument name/folder leads to path traversal. It is possible to launch the attack remotely. The complexity of an… | |
| Analizada | Alta (8.2) | 4.2% | — | Comodo Internet Security | 6/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Comodo Internet Security Premium 12.3.4.8162. This issue affects some unknown processing of the file cis_update_x64.xml of the component Manifest File Handler. The manipulation of the argument binary/params leads to os command injection. The attack… | |
| Analizada | Alta (8.2) | 0.46% | — | Comodo Internet Security | 6/7/2025 | 17/6/2026 | A vulnerability classified as critical was found in Comodo Internet Security Premium 12.3.4.8162. This vulnerability affects unknown code of the file cis_update_x64.xml of the component Manifest File Handler. The manipulation leads to improper validation of integrity check value. The attack can be initiated remotely.… | |
| Analizada | Media (6.3) | 0.27% | — | Comodo Internet Security | 6/7/2025 | 17/6/2026 | A vulnerability classified as critical has been found in Comodo Internet Security Premium 12.3.4.8162. This affects an unknown part of the component Update Handler. The manipulation leads to improper certificate validation. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The… | |
| Analizada | Media (5) | 0.22% | — | 1xinternet Simple Klaro | 13/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple Klaro allows Cross-Site Scripting (XSS).This issue affects Simple Klaro: from 0.0.0 before 1.10.0. | |
| Analizada | Alta (8.8) | 0.26% | — | 1xinternet Simple Klaro | 13/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple Klaro allows Cross-Site Scripting (XSS).This issue affects Simple Klaro: from 0.0.0 before 1.10.0. | |
| Analizada | Alta (7.1) | 0.12% | — | Samsung Internet | 4/6/2025 | 17/6/2026 | Improper handling of insufficient permission in ClientProvider in Samsung Internet installed on non-Samsung Device prior to version 28.0.0.59 allows local attackers to read and write arbitrary files. | |
| Analizada | Alta (7.1) | 0.11% | — | Samsung Internet | 4/6/2025 | 17/6/2026 | Improper handling of insufficient permission in SyncClientProvider in Samsung Internet installed on non-Samsung Device prior to version 28.0.0.59 allows local attackers to access read and write arbitrary files. |